This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XGS Backup & Restore to a new XGS (same model) restores everything, or just some things?

On an XGS, if I use Backup & Firmware > Backup & Restore > Backup I can restore this with Backup & Firmware > Backup & Restore > Restore. Does this include everything I need? Will the new XGS then functionally be the same as the old and no user would be able to tell the difference?

I'm thinking of certificates, SSH key, firewall rules, custom groups, static DHCP addresses, SSL VPN config, etc.

I don't want to expect the Restore to work and then find that I have to download a different certificate to every device to get TLS decryption to work, or to find DHCP works but all of the static machines have to be reentered. I guess part of my fear is based on not understanding the difference between Backup & Restore and Export/Import. The Backup file is small (I assume binary), while the Export is huge and slow to generate (I assume XML or something), which then worries me that I have the wrong one, or that perhaps one or the other (or both) don't actually include everythingthat I'd need to be 100% back up quickly.

I read on an older posting that if you have both devices at once, you could do a temporary HA cluster to copy everything without any downtime, but that seems to have its own potential complications -- and I've never done anything with a cluster -- so if Backup on the old and Restore on the new works perfectly, I'll live with the fairly minimal downtime. (But can't have more than minimal downtime chasing down stuff that isn't actually backed up in the Backup.)

Thanks for any tips!



This thread was automatically locked due to age.
Parents
  • Backup / Restore or HA Cluster is actually somesort of the same. But HA Cluster is only possible between the same model (and rev), but Backup/Restore is more flexible. See: https://support.sophos.com/support/s/article/KB-000036245

    Export/Import will not export everything (due security parts etc.). But Backup/restore should cover all important aspects. 

    __________________________________________________________________________________________________________________

  • Thanks for the link! I'm still slightly worried that "important stuff" might not include everything I need to have a perfectly seamless switch. That is, Backup/Restore is necessary for a swap like that, but is it entirely sufficient?

  • I am not fimiliar with a settings, which is not included. But i did not want to talk in absolutes. 

    There are "tweaks" on the database level, which are not in backups (for example a Sophos specific hotfix). 

    __________________________________________________________________________________________________________________

  • I just thought of one possibility: are the MAC addresses included and cloned? In my case, having a different MAC address for the Gateway port (Port 2) will kill connectivity until the ISP is notified and adds a new MAC address. Or I manually clone it, which would mean that I would have recorded it.

Reply
  • I just thought of one possibility: are the MAC addresses included and cloned? In my case, having a different MAC address for the Gateway port (Port 2) will kill connectivity until the ISP is notified and adds a new MAC address. Or I manually clone it, which would mean that I would have recorded it.

Children
  • If you use HA, the MAC is replaced anyway with a virtual MAC. If not, we are not overwriting the hardware MAC, if not specific replaced by you in the GUI.

    __________________________________________________________________________________________________________________